PP3 Analysis Flashcards
Four types of Business Impact Analysis (BIA)
- An initial BIA.
- A product and service BIA.
- A process BIA.
- An activity BIA.
Business continuity requirements can be defined as
the time frames, resources, and capabilities necessary to continue to deliver the prioritised products, services, processes, and activities following a disruption.
Initial BiA:
Provides high-level analysis that can be used
to develop a framework for the more detailed BIAs. It
can also be used to clarify the scope of the BC programme (typically only required first time organization conducts a BIA).
Product and Service BIA
Identify & prioritise products & services & determine
organization’s BC requirements at a strategic level.
Process BIA:
Determine process or processes required
for delivery of organization’s prioritised products and services.
Activity BIA:
Identify & prioritise activities that deliver most urgent products & services, & to determine resources
required for continuity of these activities.
Products and services are defined as
“beneficial outcomes provided by an organization to its customers, recipients and interested parties.” (Source: ISO 22301:2012)
A process is described as
“a set of interrelated or interacting activities which transforms inputs to outputs.” (Source: ISO 22301:2012) Process may be divided into a number of activities.
An activity is defined as
One or more tasks undertaken by, or for an organization, that produces or supports the delivery of one or more products and services.
MTPD
Maximum tolerable period of disruption
MAO
Maximum acceptable outage
RTO
Recovery time objectives
Terms ‘maximum tolerable period of disruption’ or ‘maximum acceptable outage’ are used to describe
“the time it would take for adverse impacts, which might arise as a result of not providing a product/service or performing an activity, to become
unacceptable.” (Source: ISO 22301:2012)
The ‘recovery time objective’ is defined as
“the period of time following an incident within which a product or service must be resumed, or activity must be resumed, or resources must be recovered.” (Source: ISO 22301:2012)
Prioritised activities is defined as
“activities to which priority must be given following an
incident in order to mitigate impacts.” (Source ISO 22301:2012)
The BIA process can be summarised as follows:
- Prioritise the organization’s products & services
by determining the MTPD for each. - Prioritise the process or processes required to deliver the organization’s most urgent products and services,
including identification of the activities that make up
those processes, if required. - Prioritise the activities that deliver the most urgent products and services, determine resources required for
continuity of these activities following an incident, as
well as their interdependencies. - Perform final analysis or consolidation of analyses which should lead to determination of BC
requirements. - Seek top management approval of BIA results.